close
The Wayback Machine - https://web.archive.org/web/20240724031914/https://github.blog/security/vulnerability-research/
Home / Security / Vulnerability research

Vulnerability research

Dedicated to advancing the understanding and detection of software vulnerabilities—and explaining the latest vulnerability research from the GitHub Security Lab. Go behind the scenes with the GitHub Security Lab, a collaborative initiative that brings together security researchers, developers, and organizations to find and fix security vulnerabilities in open source software.

Featured

We do newsletters, too

Highly curated content, articles, customer stories, events, and other great content from around the community.

Latest

BERJAYA

Gaining kernel code execution on an MTE-enabled Pixel 8

In this post, I’ll look at CVE-2023-6241, a vulnerability in the Arm Mali GPU that allows a malicious app to gain arbitrary kernel code execution and root on an Android phone. I’ll show how this vulnerability can be exploited even when Memory Tagging Extension (MTE), a powerful mitigation, is enabled on the device.

BERJAYA

mTLS: When certificate authentication is done wrong

In this post, we’ll deep dive into some interesting attacks on mTLS authentication. We’ll have a look at implementation vulnerabilities and how developers can make their mTLS systems vulnerable to user impersonation, privilege escalation, and information leakages.

The world's largest developer platform

Docs

Docs

close

Everything you need to master GitHub, all in one place.

GitHub

GitHub

close

Build what’s next on GitHub, the place for anyone from anywhere to build anything.

Customer stories

Customer stories

close

Meet the companies and engineering teams that build with GitHub.

GitHub Universe 2024

GitHub Universe 2024

close

Get tickets to the 10th anniversary of our global developer event on AI, DevEx, and security.